Publication: Article on “Clouds you can trust” in IEEE Spektrum

Christian Cachin and I published an overview on trusted clouds at IEEE Spektrum:

Christian Cachin, Matthias Schunter: A Cloud You Can Trust –
How to ensure that cloud computing’s problems—data breaches, leaks, service outages—don’t obscure its virtues, IEEE Spektrum, December 2011, pp 28-51.

Read it online at
http://spectrum.ieee.org/computing/networks/a-cloud-you-can-trust/0

W3C-Tracking Protection: Release of First Public Working Drafts

Today, the W3C Tracking Protection Working Group has released its First Public Working Drafts (FPWD):

“To address rising concerns about privacy on the Web, W3C publishes today two first drafts for standards that allow users to express preferences about online tracking:

These documents are the early work of a broad set of stakeholders in the W3C Tracking Protection Working Group, including browser vendors, content providers, advertisers, search engines, and experts in policy, privacy, and consumer protection. W3C invites review of these early drafts, expected to become standards by mid-2012. Read the full press release and testimonials and learn more about Privacy.”

This release has triggered an entry in IBM’s Privacy Blog as well as a series of news items. My involvement in the W3C DNT Working group is partially supported by the EU TClouds Project.

CfP: 9th International Conference on Trust, Privacy & Security in Digital Business (TrustBus 2012)

I’ll participate in the program committee of TrustBus 2012. The Call for papers can be found at http://www.ds.unipi.gr/trustbus12/CfPTrustBus2012.pdf:

Important Dates

Submission deadline : April 6, 2012
Notification to authors: May 11, 2012
Camera-ready version: June 10, 2012

CfP: 5th International Conference on Trust and Trustworthy Computing (Trust 2012)

I’ll participate in the Program Committee of Trust 2012. The Call for Papers can be found at http://trust.sba-research.org/CFP.html (as PDF)

TRUST 2012 is an international conference on the technical and soci-economic aspects of trustworthy infrastructures. It provides an excellent interdisciplinary forum for researchers, practitioners, and decision makers to explore new ideas and discuss experiences in building, designing, using and understanding trustworthy computing systems.

Important dates are

  • Submission due: 15 February 2012
  • Notification: 25 March 2012
  • Camera ready: 09 April 2012
  • Conference: 13-15 June 2012

 

CfP: 1st Workshop on Resilient Cyber-physical SystemS (ReSyS 2012)

I will participate in the program committee of the 1st Workshop on Resilient Cyber-physical SystemS:

Important Dates:

  • Paper submission: December 01, 2011
  • Notification of acceptance: December 15, 2011
  • Final paper submission: January 03, 2012
  • Workshop: February 28, 2012

Read more of this post

CfP: 1st European Workshop on Dependable Cloud Computing (EWDCC ’12)

I’ll participate in the program committee of the 1st European Workshop on Dependable Cloud Computing (EWDCC ’12). The call for papers can be found at the .

Important dates:

  • Submission deadline: January 27, 2012
  • Author notification: March 14, 2012
  • Final version: March 20, 2012

Read more of this post

Co-Chair of W3C Tracking Protection Standardisation Group

I’ve been invited to co-chair the Tracking Protection Working Group of the World-Wide Web Consortium.

The Tracking Protection Working Group is chartered to improve user privacy and user control by defining mechanisms for expressing user preferences around Web tracking and for blocking or allowing Web tracking elements. The group seeks to standardize the technology and meaning of Do Not Track, and of Tracking Selection Lists.

My mission as the chair is to drive the consensus-based standardisation process. My personal goal is to ensure that the privacy requirements of individuals as well as the industry requirements are met by the emerging recommendations.

Our kick-off meeting on September 21+22 in Boston MA, managed to assemble many important stakeholders such as Apple, the Center of Democracy and Privacy, ComScore, the EFF, FTC (Ed Felten), Google, the Interactive Advertising Bureau (IAB), Microsoft, Nielsen, and Yahoo in one room.

Paper at ESORICS 2011: Automated Information Flow Analysis of Virtualized Infrastructures

Today, we received an acceptance note for our submission to ESORICS 2011:

Sören Bleikertz, Thomas Gross, Matthias Schunter, Konrad Eriksson: Automated Information Flow Analysis of Virtualized Infrastructures, European Symposium on Research in Computer Security (ESORICS 2011)

You can download the paper (PDF)

Abstract
The use of server virtualization has been growing steadily, but many enterprises are still reluctant to migrate critical workloads to such infrastructures. One key inhibitor is the complexity of correctly configuring virtualized cloud infrastructures, and in particular, of isolating workloads or subscribers across all potentially shared physical and virtual resources. Imagine analyzing systems with half a dozen virtualization platforms, thousands of virtual machines and hundreds of thousands of inter-resource connections by hand: large topologies demand tool support.
We study the automated information flow analysis of heterogeneous virtualized infrastructures. We propose an analysis system that performs a static information
flow analysis based on graph traversal. The system discovers the actual configurations of diverse virtualization environments and unifies them in a graph representation. It computes the transitive closure of information flow and isolation rules over the graph and diagnoses isolation breaches from that. The system effectively reduces the analysis complexity for humans from checking the entire infrastructure, to checking a few well-designed trust rules on components’ information flow.

Graph for Mid-size Cloud

Case Study: Graph-based Model for mid-size Cloud

Read more of this post

CCSW 2011: The ACM Cloud Computing Security Workshop (Program Committee)

I’ll participate in the Program Committee of the ACM Cloud Computing Security Workshop. . Please consider submitting your latest research on cloud security.

Important Dates:

  • Submissions: July 1, 2011July 16, 2011
  • Author notification: August 4, 2010

2011-06-09 Invited Presentation at the 2011 Conference of the Swiss Telecommunications Association (ASUT)

The Swiss Telecommunications Association is a non-profit organisation that represents users and providers of telecommunication. All major Swiss telcos are members:

I gave a presentation on cloud security at the 2011 ASUT Seminar that will be held on June 09 at the Kursaal in Berne. The ASUT Seminar constitutes the #1 event for the telco industry in Switzerland.

The program can be found here, abstract here.

Enclosed you find a report about the event (in German) that has been broadcasted by the SF Tagesschau.
Tagesschau vom 09.06.2011

Read more of this post